2025 CVE Vulnerabilities

45,206 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-34287HIGH7.8Nagios XI versions prior to 2024R2 contain an improperly owned script, process_perfdata.pl, which is executed periodical...
CVE-2025-34286HIGH7.2Nagios XI versions prior to 2026R1 contain a remote code execution vulnerability in the Core Config Manager (CCM) Run C...
CVE-2025-34284HIGH8.8Nagios XI versions prior to 2024R2 contain a command injection vulnerability in the WinRM plugin. Insufficient validatio...
CVE-2025-34283MEDIUM6.5Nagios XI versions prior to 2024R1.4.2 revealed API keys to users who were not authorized for API access when using Nept...
CVE-2025-34280HIGH7.2Nagios Network Analyzer versions prior to 2024R2.0.1 contain a vulnerability in the LDAP certificate management function...
CVE-2025-34278MEDIUM5.4Nagios Network Analyzer versions prior to 2024R1 contain a stored cross-site scripting (XSS) vulnerability in the Source...
CVE-2025-34277CRITICAL9.8Nagios Log Server versions prior to 2024R1.3.1 contain a code injection vulnerability where malformed dashboard ID value...
CVE-2025-34274CRITICAL9.8Nagios Log Server versions prior to 2024R2.0.3 contain an execution with unnecessary privileges vulnerability as it runs...
CVE-2025-34273MEDIUM6.5Nagios Log Server versions prior to 2024R2.0.3 contain an incorrect authorization vulnerability that allows non-administ...
CVE-2025-34272MEDIUM6.5In Nagios Log Server versions prior to 2024R2.0.3, when a user's configured default dashboard is deleted, the applicatio...
CVE-2025-34271CRITICAL9.8Nagios Log Server versions prior to 2024R2.0.2 contain a vulnerability in the cluster manager component when requesting ...
CVE-2025-34270MEDIUM4.9Nagios Log Server versions prior to 2024R2.0.2 contain a vulnerability in the AD/LDAP user import functionality as it fa...
CVE-2025-34269Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority as it is a duplicate of CVE-2...
CVE-2025-34249Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority as it is a duplicate of CVE-2...
CVE-2025-34135MEDIUM4.4Nagios XI versions prior to 2024R1.4.2 configure some systemd unit files with permission sets that were too permissive. ...
CVE-2025-34134HIGH7.2Nagios XI versions prior to 2024R1.4.2 contain a remote code execution vulnerability in the Business Process Intelligenc...
CVE-2025-8850HIGH8.8In danny-avila/librechat version 0.7.9, there is an insecure API design issue in the 2-Factor Authentication (2FA) flow....
CVE-2025-63423HIGH7.5Each Italy Wireless Mini Router WIRELESS-N 300M v28K.MiniRouter.20190211 was discovered to store the Administrator passw...
CVE-2025-61498HIGH7.5A buffer overflow in the UPnP service of Tenda AC8 Hardware v03.03.10.01 allows attackers to cause a Denial of Service (...
CVE-2025-61141HIGH7.5sqls-server/sqls 0.2.28 is vulnerable to command injection in the config command because the openEditor function passes ...
CVE-2025-3356CRITICAL9.8IBM Tivoli Monitoring 6.3.0.7 through 6.3.0.7 Service Pack 21 could allow a remote attacker to traverse directories on t...
CVE-2025-3355HIGH7.5IBM Tivoli Monitoring 6.3.0.7 through 6.3.0.7 Service Pack 21 could allow a remote attacker to traverse directories on t...
CVE-2025-63422HIGH7.5Incorrect access control in the Web management interface in Each Italy Wireless Mini Router WIRELESS-N 300M v28K.MiniRou...
CVE-2025-63298HIGH8.2A path traversal vulnerability was identified in SourceCodester Pet Grooming Management System 1.0, affecting the admin/...
CVE-2025-62265MEDIUM5.4Cross-site scripting (XSS) vulnerability in the Blogs widget in Liferay Portal 7.4.0 through 7.4.3.111, and older unsupp...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now